- EPSS 5.32%
- Veröffentlicht 28.08.2019 19:15:10
- Zuletzt bearbeitet 21.11.2024 04:23:14
A vulnerability in the Cisco REST API virtual service container for Cisco IOS XE Software could allow an unauthenticated, remote attacker to bypass authentication on the managed Cisco IOS XE device. The vulnerability is due to an improper check perfo...
CVE-2019-12624
- EPSS 18.19%
- Veröffentlicht 21.08.2019 19:15:13
- Zuletzt bearbeitet 21.11.2024 04:23:12
A vulnerability in the web-based management interface of Cisco IOS XE New Generation Wireless Controller (NGWC) could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an ...
CVE-2019-1904
- EPSS 0.97%
- Veröffentlicht 21.06.2019 03:15:09
- Zuletzt bearbeitet 21.11.2024 04:37:39
A vulnerability in the web-based UI (web UI) of Cisco IOS XE Software could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. The vulnerability is due to insufficient CSRF protectio...
- EPSS 5.52%
- Veröffentlicht 13.05.2019 20:29:03
- Zuletzt bearbeitet 21.11.2024 04:37:33
A vulnerability in the web-based user interface (Web UI) of Cisco IOS XE Software could allow an authenticated, remote attacker to execute commands on the underlying Linux shell of an affected device with root privileges. The vulnerability occurs bec...
CVE-2019-1649
- EPSS 0.61%
- Veröffentlicht 13.05.2019 19:29:01
- Zuletzt bearbeitet 21.11.2024 04:37:00
A vulnerability in the logic that handles access control to one of the hardware components in Cisco's proprietary Secure Boot implementation could allow an authenticated, local attacker to write a modified firmware image to the component. This vulner...
- EPSS 3.41%
- Veröffentlicht 28.03.2019 01:29:00
- Zuletzt bearbeitet 21.11.2024 04:37:17
A vulnerability in the authorization subsystem of Cisco IOS XE Software could allow an authenticated but unprivileged (level 1), remote attacker to run privileged Cisco IOS commands by using the web UI. The vulnerability is due to improper validation...
- EPSS 3.39%
- Veröffentlicht 28.03.2019 01:29:00
- Zuletzt bearbeitet 21.11.2024 04:37:17
A vulnerability in the Web Services Management Agent (WSMA) function of Cisco IOS XE Software could allow an authenticated, remote attacker to execute arbitrary Cisco IOS commands as a privilege level 15 user. The vulnerability occurs because the aff...
- EPSS 3.7%
- Veröffentlicht 28.03.2019 01:29:00
- Zuletzt bearbeitet 21.11.2024 04:37:17
A vulnerability in Cisco IOS XE Software could allow an authenticated, remote attacker to execute commands on the underlying Linux shell of an affected device with root privileges. The vulnerability occurs because the affected software improperly san...
CVE-2019-1757
- EPSS 1.05%
- Veröffentlicht 28.03.2019 01:29:00
- Zuletzt bearbeitet 21.11.2024 04:37:17
A vulnerability in the Cisco Smart Call Home feature of Cisco IOS and IOS XE Software could allow an unauthenticated, remote attacker to gain unauthorized read access to sensitive data using an invalid certificate. The vulnerability is due to insuffi...
CVE-2019-1759
- EPSS 4.4%
- Veröffentlicht 28.03.2019 01:29:00
- Zuletzt bearbeitet 21.11.2024 04:37:18
A vulnerability in access control list (ACL) functionality of the Gigabit Ethernet Management interface of Cisco IOS XE Software could allow an unauthenticated, remote attacker to reach the configured IP addresses on the Gigabit Ethernet Management i...